This month's Microsoft patch releaseincludes six bulletins, addressing 12 vulnerabilities in common clientand server software, including four in a popular developmentenvironment. Topping the heap in terms of urgency is a remotelyexploitable, server side code execution vulnerability in IIS, andthat's where we'll start:
MS07-041;KB939373Vulnerability in Microsoft Internet Information Services Could Allow Remote Code Execution
This bulletin addresses a previously known issue in IIS 5.1 onWindows XP that was reported in late 2005 as a denial-of-serviceproblem. It is now known to be exploitable to run attacker code. IIS isnot running or installed by default on Windows XP.
Microsoft Internet Information Server 5.1 DLL Request Remote Code Execution Vulnerability BID...